CVE-2026-34684: Substance3D - Designer | Out-of-bounds Write (CWE-787)
Published May 12, 2026
·Updated
Substance3D - Designer versions 15.1.0 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
2 affected components
Adobe Substance 3D Designer<=15.1.0
Adobe Substance 3D Designer<=15.1.0
Event History
May 12, 2026
CVE Published
via MITRE·06:13 PM
Data Sourced
via MITRE·06:13 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-34684?
CVE-2026-34684 is classified as a high-severity out-of-bounds write vulnerability.
2
How do I fix CVE-2026-34684?
To remediate CVE-2026-34684, update Adobe Substance 3D Designer to the latest version beyond 15.1.0.
3
What could happen if CVE-2026-34684 is exploited?
Exploiting CVE-2026-34684 could allow an attacker to execute arbitrary code in the context of the current user.
4
What versions of Substance 3D Designer are affected by CVE-2026-34684?
Adobe Substance 3D Designer versions up to and including 15.1.0 are affected by CVE-2026-34684.
5
Is user interaction required to exploit CVE-2026-34684?
Yes, exploitation of CVE-2026-34684 requires some form of user interaction.